HIGH
insumermodel
CVE published 2026-10-07
CVE-2026-104891
CVE-2026-104891: The mppx-condition-gate packages do not validate the relationship between the credential source and the payload, allowing an attacker to obtain free access to a route that should have been paid for by naming any qualifying address in the credential source. This vulnerability affects the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate. Defenders should asse [truncated]